CVE-2026-0239
Chronosphere Chronocollector Information Disclosure Vulnerability
Severity
Medium 4.9
CVSS 4.0
Exploited
Not listed
EPSS
0.002
7.0th percentile
Discovered by
Vendor
Published by the vendor
Published
May 13, 2026
Assigned by palo_alto
Description
An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.
Weakness: CWE-497
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported affected versions (1)
- Palo Alto Networks · Chronosphere Chronocollector
Credit
Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.
Vendor remediation
Version Suggested Solution Chronosphere Chronocollector Upgrade to v0.116.0 or later.